
GIAC Cloud Penetration Tester
Domain 2Objective 2
Cloud CLI and Application Mapping GCPN Practice Questions (Page 4)
Part of the Cloud Service Discovery and Reconnaissance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
Questions 16–20
- 16
Which tool is commonly used for web application fingerprinting?
Select an answer first - 17
While mapping a cloud-hosted application, you discover an API endpoint at `/api/v2/users`. You need to determine which HTTP methods are supported and whether authentication is required. Which approach is most effective?
Select an answer first - 18
In the Azure CLI, which command is used to authenticate a user to Azure?
Select an answer first - 19
A penetration tester is analyzing a cloud-hosted API that uses OAuth 2.0 for authentication. The tester needs to discover the API's endpoints, methods, and the authentication mechanism. Which approach would be most effective?
Select an answer first - 20
A junior tester is starting a cloud assessment and has been given a set of AWS access keys. The tester wants to verify that the keys work and see which IAM user they belong to. Which AWS CLI command should be run first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.